The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.28-rc1
http://rhn.redhat.com/errata/RHSA-2009-0264.html
http://secunia.com/advisories/32510
http://secunia.com/advisories/32918
http://secunia.com/advisories/32998
http://secunia.com/advisories/33180
http://secunia.com/advisories/33556
http://secunia.com/advisories/33858
http://www.debian.org/security/2008/dsa-1681
http://www.debian.org/security/2008/dsa-1687
http://www.mandriva.com/security/advisories?name=MDVSA-2008:234
http://www.openwall.com/lists/oss-security/2008/11/03/2
http://www.redhat.com/support/errata/RHSA-2009-0014.html
http://www.securityfocus.com/bid/32096
http://www.ubuntu.com/usn/usn-679-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/46327
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11635
OR
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
67800 | Oracle Linux 5 : kernel (ELSA-2009-0264) | Nessus | Oracle Linux Local Security Checks | critical |
67790 | Oracle Linux 4 : kernel (ELSA-2009-0014) | Nessus | Oracle Linux Local Security Checks | high |
60532 | Scientific Linux Security Update : kernel on SL5.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | critical |
60520 | Scientific Linux Security Update : kernel on SL4.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | high |
43727 | CentOS 4 : kernel (CESA-2009:0014) | Nessus | CentOS Local Security Checks | high |
38027 | Mandriva Linux Security Advisory : kernel (MDVSA-2008:234) | Nessus | Mandriva Local Security Checks | high |
37683 | Ubuntu 6.06 LTS / 7.10 / 8.04 LTS / 8.10 : linux, linux-source-2.6.15/22 vulnerabilities (USN-679-1) | Nessus | Ubuntu Local Security Checks | high |
35645 | RHEL 5 : kernel (RHSA-2009:0264) | Nessus | Red Hat Local Security Checks | critical |
35381 | RHEL 4 : kernel (RHSA-2009:0014) | Nessus | Red Hat Local Security Checks | high |
35174 | Debian DSA-1687-1 : linux-2.6 - denial of service/privilege escalation | Nessus | Debian Local Security Checks | high |
35036 | Debian DSA-1681-1 : linux-2.6.24 - denial of service/privilege escalation | Nessus | Debian Local Security Checks | critical |
801465 | CentOS RHSA-2009-0014 Security Check | Log Correlation Engine | Generic | high |